PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40765 collectchat CVE debrief

CVE-2026-40765 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in the collectchat plugin versions up to 2.4.9. The vulnerability has a CVSS score of 7.1 and is considered HIGH. It was published on June 17, 2026, and last modified on the same day. The vulnerability allows attackers to inject malicious scripts into the application. Users of the collectchat plugin should take immediate action to mitigate this vulnerability. The CVE record and NVD detail provide further information on this vulnerability.

Vendor
collectchat
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

Administrators and users of the collectchat plugin versions up to 2.4.9 should be aware of this vulnerability and take necessary actions to secure their installations. Web application security teams and developers using this plugin should prioritize patching or mitigating this vulnerability.

Technical summary

CVE-2026-40765 is an Unauthenticated Cross Site Scripting (XSS) vulnerability in the collectchat plugin. The vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L. It was reported by [email protected] and is associated with CWE-79. The vulnerability affects collectchat plugin versions up to 2.4.9.

Defensive priority

High

Recommended defensive actions

  • Update the collectchat plugin to the latest version.
  • Implement web application firewall (WAF) rules to detect and prevent XSS attacks.
  • Use input validation and output encoding to prevent script injection.
  • Monitor the application for suspicious activity.
  • Restrict access to the collectchat plugin to authorized users only.
  • Consider using a security plugin or service to detect and mitigate vulnerabilities.

Evidence notes

The vulnerability was reported by Patchstack and is documented in the CVE record and NVD detail. The CVSS score and vector provide a measure of the vulnerability's severity.

Official resources

public